# Mac 上的 Hermes Agent 安全：监控它的网络访问

> Nous Research 的 Hermes Agent 会运行终端命令和一个消息网关。了解其文档所述的审批和沙箱机制，以及 FireAI 如何标记新的目的地和上传峰值。

FireAI Security & Research Team (HisnLabs) · Published 2026-10-04
Canonical: https://hisnlabs.com/zh/blog/mac-hermes-agent-anquan-jiankong

Hermes Agent 是 Nous Research 推出的开源智能体，可以使用终端、搜索网页，并通过即时通讯 App 作出回答。“hermes agent security”和“is Hermes Agent safe”之类的搜索归结为两个问题：它能在你的 Mac 上运行什么，以及它的流量可以去往何处。本文依据该项目自己的文档和已发表的报道回答这两个问题，然后解释 HisnLabs 开发的 macOS 网络防火墙 FireAI 如何监视它的连接。

## Hermes Agent 是什么，如何在 Mac 上运行

其[代码仓库](https://github.com/NousResearch/hermes-agent)描述了一个自我改进的智能体，它内置学习循环，可以从经验中创建技能。它由 Nous Research 开发，主要使用 Python 编写，网页界面使用 Node.js 组件，以 MIT 许可证发布。在 macOS 上，它通过一行脚本安装（`curl -fsSL https://hermes-agent.nousresearch.com/install.sh | bash`）。它支持 Nous Portal、OpenRouter、OpenAI、Anthropic 和自定义端点，其消息网关支持 Telegram、Discord、Slack、WhatsApp、Signal 和电子邮件。

## 它能访问什么

README 列出了 40 多种集成工具，包括网页搜索和终端访问，以及七种终端后端：local、Docker、SSH、Singularity、Modal、Daytona 和 Vercel Sandbox。在 local 后端上，命令以启动 Hermes 的账户所具有的权限运行。

## 文档所述的权限模型

其[安全文档](https://hermes-agent.nousresearch.com/docs/user-guide/security)描述了纵深防御机制。

- 审批有三种模式：smart（由模型评估风险）、manual（始终询问）和 off。YOLO 模式会跳过询问，但针对灾难性命令的硬性拦截列表仍然适用。
- Docker、Modal 和 Daytona 等容器化后端会隔离命令；在这些后端中会跳过危险命令检查，因为容器本身就是边界。
- 网关访问默认被拒绝，需使用由运营者批准的私信配对码，并设有平台级和全局允许列表。
- 网络控制包括 SSRF 防护，可拦截私有地址段、环回地址和云元数据端点。
- `~/.ssh/` 和 `~/.aws/` 等受保护路径被硬性禁止写入，子进程收到的是经过过滤的环境。

这些是厂商的声明，而不是独立测试的结果。文档没有公布 Hermes 所联系域名的固定列表；这些域名取决于你配置的模型提供方和消息平台。

## 有记录的事件

GitHub Advisory Database 收录了 CVE-2026-9366，这是 0.15.0 之前版本中的一个中等严重程度的注入问题，已在 0.15.0 中修补 [(公告)](https://github.com/advisories/GHSA-pgp4-xr4j-h5cg)。另外，Hunt.io 和 Unit 42 报告了攻击者以 YOLO 模式运行 Hermes Agent 攻击他人服务器的情况 [(Hunt.io)](https://hunt.io/blog/thailand-ministry-finance-targeted-with-hermes-ai-agent) [(BleepingComputer)](https://www.bleepingcomputer.com/news/security/hacker-uses-deepseek-ai-to-autonomously-attack-vulnerable-servers/)。这些案例涉及的是攻击者选用了该工具，而不是该工具被报告存在缺陷。详情见我们的[事件汇总](https://hisnlabs.com/en/blog/openclaw-hermes-agent-security-incidents-2026)。

> 能够运行命令的智能体，也可能建立你意料之外的连接。FireAI 显示每一个新的目的地，并允许你拦截它。可免费试用。 [Download FireAI for Mac](https://hisnlabs.com/en/download)

## 用 FireAI 监视 Hermes Agent

FireAI 是 HisnLabs 开发的 macOS 设备端防火墙。其 [Agent profile](https://hisnlabs.com/zh/docs/agent-profile) 功能把 Hermes Agent 列为它识别的 19 种 AI 智能体之一。由于 Hermes Agent 在 python 下运行，FireAI 通过运行时所运行的脚本来识别它，这是 Agent profile 针对 node、bun、deno 和 python 智能体所采用的方法。智能体的子进程，例如它启动的 shell、git 或 curl，会通过向上追溯父进程而归属于它。随后，FireAI 会在最初 3 天学习 Hermes Agent 通常联系哪些目的地，按域名分组，在此期间不标记任何内容。此后，首次出现的目的地会在 Suggestions、AI agents 卡片和 [Quick Review](https://hisnlabs.com/zh/docs/quick-review-suggestions) 中被标记。上传峰值也会被标记：某一小时内该智能体的上传量至少是其此前最繁忙一小时的 4 倍，且不少于 25 MB。

![FireAI 的 Activity 列表按“herm”筛选：一个 python3.14 进程正在连接 hermes-agent.nousresearch.com，显示的是 Hermes Agent 角色形象，而不是空白图标。](https://cdn.hisnlabs.com/blog/monitor-hermes-agent-activity.png)

*Mac 上 FireAI 的 Activity 列表：Hermes Agent 自带的 Python 正在连接 hermes-agent.nousresearch.com，并标有 Hermes Agent 角色形象。*

FireAI 只使用元数据，即主机名和字节数，从不读取连接的有效载荷。默认情况下，它只作标记，把决定留给你。在 Agent profile 安全模式下，它会更进一步：学习结束后，连接到基线之外目的地的请求会被拦截，直到你点按 Allow；Keep blocked 则会把这次拦截变成一条在所有模式下都有效的规则。

### 逐步设置

1. 安装 FireAI 并完成首次运行设置，参见 [Install and finish setup](https://hisnlabs.com/zh/docs/install-and-finish-setup)。
2. 像平常一样使用 Hermes Agent 3 天。FireAI 会在后台学习其目的地，此时还不会标记任何内容。
3. 打开 Suggestions，找到 AI agents 卡片。出现标记时，阅读那句平实的说明，然后在 Quick Review 中向左滑动拦截，或向右滑动选择“It’s fine”（没问题）。
4. 如果希望智能体只访问它已经在用的地方，请在安全模式菜单中选择 Agent profile，它与 Home、Coffee shop、Paranoid 和 Under attack 并列。
5. 有内容被拦截时，打开 AI agents 卡片，选择 Allow 将其加入基线，或选择 Keep blocked 创建拦截规则。

## 局限

- FireAI 无法阻止提示注入。它通过标记数据离开你的 Mac 的路径并允许你拦截该路径来限制损害。
- FireAI 看不到 Hermes Agent 的提示、MCP 工具的内容、技能，也看不到它读取了哪些文件，因为 TLS 隐藏了有效载荷，而且 FireAI 并不在智能体内部。
- Hermes Agent 是按脚本名称匹配的，因此 FireAI 只是对它进行标注，而不是验证：只有 Claude Code、Claude 和 Cursor 会根据其开发者的签名进行核验。
- Hermes 在 Docker 或远程后端中运行的命令发生在你的 Mac 的进程树之外，因此 FireAI 看到的是来自 Docker 或 SSH 进程的连接，而不是来自其中命令的连接。
- FireAI 不能取代 Hermes 自身的审批、允许列表或沙箱，也不会审查它创建的技能。
- 在 3 天学习期内不会标记任何内容，上传峰值只会被标记，不会被拦截。
- 由于目的地按域名分组，智能体已在使用的域名下的新服务器会被视为已知。

完整的功能说明见 [Agent profile 文档](https://hisnlabs.com/zh/docs/agent-profile)。另有一篇相关指南介绍 [OpenClaw](https://hisnlabs.com/en/blog/monitor-openclaw-network-mac-fireai)。

FireAI 识别的其他智能体也有各自的指南：[Claude Code](https://hisnlabs.com/en/blog/monitor-claude-code-network-mac-fireai)、[Claude 桌面 App](https://hisnlabs.com/en/blog/monitor-claude-desktop-app-network-mac-fireai)、[Cursor](https://hisnlabs.com/en/blog/monitor-cursor-network-mac-fireai)、[ChatGPT Mac App](https://hisnlabs.com/en/blog/monitor-chatgpt-mac-app-network-fireai)、[OpenAI Codex CLI](https://hisnlabs.com/en/blog/monitor-openai-codex-cli-network-mac-fireai)、[OpenClaw](https://hisnlabs.com/en/blog/monitor-openclaw-network-mac-fireai)、[Gemini CLI](https://hisnlabs.com/en/blog/monitor-gemini-cli-network-mac-fireai)、[GitHub Copilot CLI](https://hisnlabs.com/en/blog/monitor-github-copilot-cli-network-mac-fireai)、[Amp](https://hisnlabs.com/en/blog/monitor-amp-agent-network-mac-fireai)、[Qwen Code](https://hisnlabs.com/en/blog/monitor-qwen-code-network-mac-fireai)、[opencode](https://hisnlabs.com/en/blog/monitor-opencode-network-mac-fireai)、[Aider](https://hisnlabs.com/en/blog/monitor-aider-network-mac-fireai)、[Goose](https://hisnlabs.com/en/blog/monitor-goose-agent-network-mac-fireai)、[Crush](https://hisnlabs.com/en/blog/monitor-crush-agent-network-mac-fireai)、[Windsurf](https://hisnlabs.com/en/blog/monitor-windsurf-network-mac-fireai)、[Kiro](https://hisnlabs.com/en/blog/monitor-kiro-network-mac-fireai)、[Trae](https://hisnlabs.com/en/blog/monitor-trae-network-mac-fireai)、[Meta 的 Muse](https://hisnlabs.com/en/blog/monitor-muse-meta-network-mac-fireai)、[由 Python 或 Node 运行的任何 AI 智能体](https://hisnlabs.com/en/blog/monitor-any-ai-agent-mac-python-node-fireai)。

## FireAI 和 HisnLabs 在其中扮演的角色

Hermes Agent 可以以你的身份运行终端命令。FireAI 显示它接下来连接到哪里，并且可以拦截。

FireAI 是 HisnLabs 自己的产品：一款直接在 Mac 上运行的 AI 防火墙。它用通俗易懂的语言显示你的应用建立的每一个连接，并让你决定哪些数据可以离开你的 Mac——它的 AI 在本地运行，因此你的流量永远不会发送给我们或任何其他人。HisnLabs 的安全研究团队负责让这些判断保持准确：归类哪些域名只是普通的遥测、哪些属于真正的服务，追踪连接背后的国家和网络，并用真实的流量模式训练设备端模型（FireAI Pilot 功能）——这一切都不会离开你的 Mac。

你可以阅读它背后的技术决策，或试用 FireAI 17 天：[HisnLabs 出品的 FireAI](https://hisnlabs.com/zh/download)。

## Sources

- [Hermes Agent repository (README)](https://github.com/NousResearch/hermes-agent)
- [Hermes Agent documentation: Security](https://hermes-agent.nousresearch.com/docs/user-guide/security)
- [GitHub Advisory Database: hermes-agent injection vulnerability, CVE-2026-9366](https://github.com/advisories/GHSA-pgp4-xr4j-h5cg)
- [Hunt.io, 23 July 2026: Thailand Ministry of Finance targeted with Hermes AI agent running unattended](https://hunt.io/blog/thailand-ministry-finance-targeted-with-hermes-ai-agent)
- [BleepingComputer, 31 July 2026: Hacker uses DeepSeek AI to autonomously attack vulnerable servers](https://www.bleepingcomputer.com/news/security/hacker-uses-deepseek-ai-to-autonomously-attack-vulnerable-servers/)
- [FireAI docs: Agent profile](https://hisnlabs.com/en/docs/agent-profile)
